Visible to the public Analysis of Access Control Policy Updates Through Narrowing

TitleAnalysis of Access Control Policy Updates Through Narrowing
Publication TypeConference Paper
Year of Publication2016
AuthorsBertolissi, Clara, Talbot, Jean-Marc, Villevalois, Didier
Conference NameProceedings of the 18th International Symposium on Principles and Practice of Declarative Programming
PublisherACM
Conference LocationNew York, NY, USA
ISBN Number978-1-4503-4148-6
Keywordsaccess control policies, differentiation, Human Behavior, narrowing, pubcrawl, Resiliency, Scalability, Security Policies Analysis, term-rewrite systems
Abstract

Administration of access control policies is a difficult task, especially in large organizations. We consider the problem of detecting whether administrative actions can yield in policies where some security goals are compromised. In particular, we are interested in problems generated by modifications -- such as adding/deleting elements to/from the set of possible users or permissions -- of policies specified as term-rewrite systems. We propose to use rewriting techniques to compare the behaviors of the modified version and the original version of the policy. More precisely, we use narrowing to compute counter-examples to the equivalence of rewrite-based policies. We prove that our technique provides a sound and complete way to recursively enumerate the set of counter-examples, even when this set is not finite, or when a mistake of the administrator makes one or both systems non-terminating.

URLhttp://doi.acm.org/10.1145/2967973.2968605
DOI10.1145/2967973.2968605
Citation Keybertolissi_analysis_2016